Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-3956

Опубликовано: 02 июл. 2016
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.

РелизСтатусПримечание
artful

ignored

end of life
bionic

ignored

end of standard support, was needed
cosmic

not-affected

3.8.3
devel

not-affected

3.8.3
disco

not-affected

3.8.3
eoan

not-affected

3.8.3
esm-apps/bionic

released

3.5.2-0ubuntu4.1.18.04.1~esm1
esm-apps/focal

not-affected

3.8.3
esm-apps/jammy

not-affected

3.8.3
esm-apps/xenial

released

3.5.2-0ubuntu4.1.16.04.1~esm1

Показывать по

EPSS

Процентиль: 84%
0.02387
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

redhat
около 9 лет назад

The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.

CVSS3: 7.5
nvd
почти 9 лет назад

The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.

CVSS3: 7.5
debian
почти 9 лет назад

The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js ...

github
почти 7 лет назад

npm Token Leak in npm

EPSS

Процентиль: 84%
0.02387
Низкий

5 Medium

CVSS2

7.5 High

CVSS3